Where
-Infinity
0

Vendor Risk Score

See how gvisor compares to other vendors in security performance

View Risk Score →
Severity
9.3
Path Traversal
AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H

A path traversal vulnerability was found in gvproxy, the network forwarder provided by the gvisor-tap-vsock package. The unauthenticated /services/forwarder/expose endpoint does not validate the caller-supplied socket path, allowing an attacker to delete arbitrary files on the host system.

1 / 2
Source: MITRE
First published (updated )
Severity
7

A path-traversal flaw was found in gvproxy (gvisor-tap-vsock) in the port-forwarder's /services/forwarder/expose REST endpoint. When invoked with protocol=unix, the caller-supplied local field was passed without any validation to os.Remove() followed by net.Listen("unix", ...) on the host filesystem. Because this endpoint is exposed unauthenticated on the VM gateway (192.168.127.1:80), a process inside the guest VM — including an unprivileged container — could send a single HTTP POST to delete an arbitrary file owned by the gvproxy user on the host and replace it with a unix-socket inode. This crosses the container/VM-to-host isolation boundary, allowing destruction of sensitive host files (SSH keys, kubeconfig, shell/registry configuration) and denial of service. The issue was fixed by removing the os.Remove() call so pre-existing files can no longer be deleted or overwritten.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203